Tuesday, December 11, 2007
Source Code May Set Us Free
Of course, Minnesota is not the only state where this has been brought up in a defense motion to suppress. I understand that to date the manufacturer of this particular device has refused to grant access to the code, although I would welcome corrections to that understanding since I've only learned it through indirect sources.
Regardless of the facts or outcome of the particular battle between the DUI bar and the manufacturer (which in the end is not a battle we're well equipped to analyze other than as it deals with source code), the Cyberspace practitioner should already be well equipped to understand the fundamental pieces of this dispute. The manufacturer is undoubtedly claiming a right to maintain its source as a trade secret, and has so far only allowed its software to be distributed in object code (or lower) format that is not reviewable by human beings. That may well be its right under trade secret law (although we must leave open the possibility of arguments to be made on public policy grounds, or that somehow the manufacturer in this case waived its rights). Some, on the other hand, might argue that a business model based on proprietary code is not a wise one to follow where courts are more and more willing to demand openness. Could this manufacturer find its business model is ultimately a reason for a competitive manufacturer with a non-proprietary business model to step in and take business away? It all remains to be seen of course, and it's an interesting intersection between our world and another one.
Saturday, December 08, 2007
DC Bar Pipes Up on Inadvertent Disclosure of Metadata
The usual admonition to the lawyer doing the sending was there. Pay attention, learn what metadata is, and remove it if it might disclose privileged or otherwise confidential client data -- failure to so remove might itself be an ethical violation on the part of the sending lawyer. No controversy there.
The interesting part is that DC has joined the small chorus of states that have come out contrary (more or less) to the ABA's opinion on what the lawyer on the receiving end should do. Recall that the ABA's point is that the rules are essentially silent on taking advantage of metadata that an adversary should have removed from a document, although they do not go so far as to formally bless the practice. The abstract for Formal Opinion 06-442 (August 5, 2006) Review and Use of Metadata states, "The Model Rules of Professional Conduct do not contain any specific prohibition against a lawyer’s reviewing and using embedded information in electronic documents, whether received from opposing counsel, an adverse party, or an agent of an adverse party." But, at least two other states have formally come out against this view, Alabama and New York. We summarized those positions here. Alabama, for example, strictly prohibits mining of an opponents metadata: "Absent express authorization from a court, it is ethically impermissible for an attorney to mine metadata from an electronic document he or she inadvertently or improperly receives from another party."
The DC bar has struck a somewhat less harsh standard. "A receiving lawyer is prohibited from reviewing metadata sent by an adversary only where he has actual knowledge that the metadata was inadvertently sent." So, if the receiving lawyer is equally ignorant of how this inadvertent disclosure of metadata occurred, the receiving lawyer is free to use the data!
But, I am not sure how that plays out in practice, and even the opinion seems to acknowledge this. If you see data in the received document that is clearly unintentionally disclosed because it's obviously of a nature that the other side wouldn't want you to know, you're essentially deemed to have the actual knowledge cited in the rule.
Such actual knowledge may also exist where a receiving lawyer immediately notices upon review of the metadata that it is clear that protected information was unintentionally included. These situations will be fact-dependent, but can arise, for example, where the metadata includes a candid exchange between an adverse party and his lawyer such that it is “readily apparent on its face” that it was not intended to be disclosed.
One might think that pretty much anything you might find in an adversary's inadvertent disclosure that you might find useful in your then-current dispute or negotiation or whatever is going on would fall in the category of stuff that the other side would have not wanted disclosed. Thus, the actual knowledge standard is probably only helpful to the extent meaningless or valueless information is inadvertently disclosed, which might avoid an ethics battle over trivial issues.
So, for the most part, DC lawyers are on notice that if they find meta-goodies in the other side's documents, they must immediately stop using it or examining it, and must "notify the sending party and abide by the instructions of the sending party regarding the return or destruction of the writing."
(I especially liked one aspect of this issuance, which was to clearly distinguish documents created by the other side for purposes of the inter-lawyer discussions versus documents being delivered under a discovery or other court order. In short, if it's evidence, you can't delete the metadata before you send it to the other side, since the metadata is itself part of the evidence. One would hope that this would evident without explanation, but with the ubiquitous use of metadata scrubbers coming into play now we should be careful to avoid unintentionally using them where inappropriate!)
It's also pretty late notice, but ALI-ABA, one of the educational arms of the American Bar Association, is giving a webinar entitled "Confidentiality and Ethics in a Wired World." Check it out soon, since it fires up on Tuesday December 11.
Saturday, October 27, 2007
"To" vs. "BCC": An Oldie but Goodie Strikes Again
I can't vouch for this story other than what we read here, but for what it's worth it's a good reminder to us all. There are reports out that an email was sent out by the US House Judiciary Committee to a group of people who had sent in anonymous notes to a whistle blower tip-box. The email was reminding all of how their identities were going to be kept secret.
Of course -- You guessed it -- The email was sent simultaneously to 150 anonymous tipsters by putting each of their email addresses into the "TO" field. Thus, everybody on the mailing list now knows the email addresses of the other 149. (Plus, all of the recipients were probably annoyed at having to scroll down through 7 inches of addresses before they got to the message!) The problem would have been mostly avoided by simply putting the recipients' addresses into the BCC field rather than the TO field. (Even then, the ISP that originally processes the email from the sender certainly has all of the BCC list on its logs, at least for some period of time, so it's not a totally safe maneuver.)
Without getting into the almost certain political fun that will follow, we can take this as a lesson. While we all work to stay up to date on the most cutting edge of exploits and security tactics, don't let the old ones fall out of sight and out of mind. The oldies but goodies are just as likely to bite you today as they were when they were new.
Monday, October 08, 2007
Electronic Contracting versus Laziness
In each of these matters, one party set up a system to implement something electronically, either through incorporation in one 'contract' of another set of terms posted on the Web, or through the use of a purported click-through system. But, the party who found himself on the enforcement side of those purported terms or contracts challenged their incorporation or enforcement. Let us take a quick look at two of these examples.
In Federal Trade Comm. v. Cleverlink Trading Ltd., 2007 WL 2875626 (USDC N.D.Ill. No. 05 C 2889), the FTC was doing battle over the remaining assets of the losing defendant in a CAN-SPAM enforcement action. At issue was whether a contract that Cleverlink's former credit-card service, Oceanic, claimed was in place would give the erstwhile Cleverlink's money to that provider or leave it for the FTC. Oceanic and its leader, a Mr. Sholes, admitted they had no signed copy of the contract. But, they did claim they sent an email to Cleverlink that contained a link to an application for the service. "Sholes contends that Cleverlink would have had to click an "Accept" box and then digitally sign the document. [Later], Sholes sent an email to his attorney containing lines of computer code. Sholes stated in the email that the lines of code show that an email was sent to Cleverlink on March 11, 2005 with information on the processing agreement.
One might then hope that Mr. Sholes would have put his computer folks on the stand, maybe to do so little as to authenticate the business records purportedly portrayed in that email, or even better to explain what the email might mean and why. But, I can only gather that he rested his case on nothing more than his email. As we might guess, that did not cut it.
Without explanation, this Court cannot understand the lines of computer code in Sholes' email. Although Sholes stated in his email that the code lines came from Oceanic's servers, he had no first-hand knowledge regarding how and from where the code was retrieved. Sholes also could not interpret the code lines and explain how they can be read to prove that an email was sent to Cleverlink with a link to the [agreement]. Relief Defendants have provided no affidavit or testimony from anyone with actual knowledge of how and from where the code lines were retrieved. Likewise, there is no affidavit deciphering the lines of computer code. Even if the lines of codes proved that an email was sent to Cleverlink, [the card provider] still would be several steps from establishing that Cleverlink accepted the [agreement] submitted to the Court. First, there is no evidence that Cleverlink responded to the email or otherwise visited Oceanic's Web site. Sholes testified that any such evidence was deleted from Oceanic's servers before the FTC served Oceanic. Second, there is no evidence that whatever document was linked in Sholes' email contained the increased chargeback fees [at issue in this matter]. In this regard, Sholes did not retain a copy of the [agreement] and has indicated uncertainty regarding its exact terms. In the end, [Oceanic has] no competent evidence that Cleverlink electronically accepted the terms of the MPPSA.
So class, can you go through that last paragraph and put together a check-list for your next client who plans to proffer an electronically-solemnized agreement in court?
(Thanks to committee member Eric Goldman for pointing this one out to me.)
The other case in mind is Manasher v. NECC Telecom, USDC E.D. Mich., No. 06-10749, 9/18/07). Here, telephone company NECC attempted to incorporate terms in the parties' contract that NECC had posted on the web -- A technique our Cyberspace folks have viewed favorably, but only if the incorporation is clear and understandable, and is done in a manner where the other party is clearly shown to have taken an action to agree. Here, the telephone company did just about everything it could to do it incorrectly. It signed up the customers over the phone without mention of a contract, it started to provide the services without any need for the customer to indicate agreement with terms, and it tried to incorporate its web terms by burying a line deep inside of the mailed invoice:
After the phone service began, Plaintiffs received an invoice. The second page of the invoice has five boxes containing five statements. The titles of the five statements are: (1) Recurring Fee; (2) Referral Discount 5%; (3) Preferred Customer Plan 'PCP,' Standard Customer Plan 'SCP;' (4) Rates; and (5) Agreement (Disclosure and Liabilities). [Motion, Exhibit D and E]. The fifth box, containing the statement regarding the 'Disclosure and Liabilities' is at issue. The statement provides "NECC's Agreement 'Disclosure and Liabilities' can be found online at www.necc.us or you could request a copy by calling us at (800) 766 2642."
NECC argued that this was adequate to incorporate the text of 'Disclosures and Liabilities', which was in fact a set of purported contract terms including an arbitration clause that was at stake in this suit. The court did not agree.
The language does not betray a clear intent that the Disclosure and Liabilities Agreement be considered part of the contract between the parties. NILAC, supra. Nothing in the statement clearly indicates that the Disclosure and Liabilities Agreement applies to the service contract between the parties, that it forms any part of the agreement between the parties, or that it is intended to be incorporated into the agreement between the parties. The statement merely informs the reader of where to find "NECC's Agreement 'Disclosure and Liabilities.'" Further, the statement is the last of five statements, written in plain text, on the second page of the invoice. There are no allegations of any other references to the Disclosure and Liabilities Agreement either in writing, or in the verbal dealings with Defendant. Thus, the Disclosure and Liabilities Agreement is not incorporated by reference....
I believe that had each of the parties setting up the systems in the above cases simply followed, both in their legal analysis as well as in their implementation, the simple principles our group's authors have long espoused, none of this would have come to pass (for them at least...). If you haven't reviewed them recently, take a new look at the two seminal articles published by members of our Committee -- The original Click-Through article, and the later Browse-Wrap article. Professor Christina Kunz and her team of authors in each article have provided clear pathways towards successful implementation.
Of course, it's up to each of you lawyers advising your clients to ensure that these principles actually get followed on the ground in a meaningful manner. Our jobs do not end when we've written text of the agreements. We must be aware of the process used to get those contracts in front of others, and challenge those processes if they do not lead to clean and admissible evidence. Alternatively, if we allow our clients to take lazy ways through these processes, we are likely to be getting called out later when the contracts fail to be enforced because they were never entered into in the first place!
Monday, August 27, 2007
Innovation without Permission
The company claims that in the current environment of severe cut-backs, company IT departments probably won't be able to satisfy a company's application development needs. The frustrated employees will need to turn elsewhere.
“The generation that is sitting in their dorm rooms building Facebook applications is going into the workplace in the next few years,” Mr. Burton said. “The whole mindset is innovation without permission.”
How should in-house lawyers respond to this trend and these tools? Sounds like a project for CAIT (Committe on Corporate Aspects of IT). What do you think Don?
Sunday, August 12, 2007
Boing Boing claims Google Video robs customers of the videos they "own"
Why not kick this one around at the meeting.
Saturday, August 11, 2007
Committee Forum: Website Agreements -- I Didn't Agree to Those Terms, Did I?
The Committee continued its long-standing leadership in the electronic contracting arena. After our groundbreaking articles on Click-Through Agreements and Browse-Wrap Agreements, it was time to revisit some new topics that we've seen bouncing around in recent years.
After spending some time in reviewing the prior scholarship, Chris Kunz, Kathy Porter and Juliet Moringiello went over recent cases involving modifications and amendments to contracts done via electronic means. The cases are still in flux, but we see trends that tell us that principals of 'notice' and basic fairness still apply. The biggest sit-up-and-take-notice moment was discussions of a growing trend in a number of states that find that terms in a contract that allow amendment by unilateral postings on a web site may not only be unenforceable on their own, but might even go so far as to cause the original underlying contract itself to be voided!
Eran Kahana and John Ottaviani spoke on the recent discussions (and very thin case law) regarding 'bots' and their abilities to enter into contracts. While it is pretty clear that 'bots' are recognizable players in a contracting situation, we still wait to see how far the courts are willing to let those things play out.
Putting the Winter Back into Winter Working Meeting!
The event will be held at the Executive Conference Center at the Mall of America in Bloomington.
The world-famous mall is very near to the Minneapolis-St Paul Airport. We will have a block of rooms at a very reasonable price at the Embassy Suites Minneapolis Airport. Free shuttles from the airport and to the mall will be available. And, the MSP International Airport is a very easy airport to reach.
Along with the mall itself, those with families might consider the nearby Waterpark of America as a reason to bring some kids along.
We do promise to keep everybody warm!
More details to follow -- But, we want you all to hold the dates and plan to be with us for Winter Working Meeting 2008!
Friday, August 10, 2007
Program: Net Neutrality--The Great US and Global Debate--What it is About and Why Your Clients Should Care
Hank Judy and Tom Laudise, co-chairs of the Internet Law Subcommittee, gathered a first-class panel of speakers for the Net Neutrality program held on Friday morning at the 2007 Annual Meeting. The program was sponsored by the Business Section Technology Committee, and co-sponsored by the Cyberspace Committee and the Section of Science and Technology.
Greg Luib from the FTC first gave a helpful overview of the debate, which does require some technological background to follow and he gave it the yeoman's effort to teach a bunch of lawyers how routers work. My own common sense suggests that trying to summarize that description is unwise, particularly since one of Greg's points was that
Then, the debate began. Examples on one side -- Imagine you placed a phone call to reach your local pizza joint, and the phone company suggests that instead of your choice of pizza it might be nicer if you tried their chosen pizza provider, but if you really want to talk to your original joint please hold for three minutes (while others are already placing their orders for hot juicy pizzas from the preferred pizza provider, or PPP). The stronger statements were along the lines of "Don't break the Internet." The argument is that by ensuring that even the smallest of new content provider can get access to the Internet consumer, we can have a chance to allow a garage company of today to become an important player, be it by financial success to become the next Google, or be it by having an ability to reach people it couldn't otherwise reach through traditional media or means of communication.
On the other side of the debate, it was suggested that it is over-reacting to enter into regulation prior to knowing if there is a harm to be resolved, as well as questioning if consumers are being harmed in any of the discussed scenarios. "Balancing the risks is a complex empirical question." Another primary argument is that the ability to add new networks, and create further competition, is a better way to resolve the problem rather than to regulate those networks that already exist. The economic arguments often followed a line that regulating today may lead to results we cannot anticipate. Quoting panelist Michael Katz from an article he recently published, "Public policy should intervene where anti-competitive actions can be identified and the cure will not be worse than the disease. Policymakers must tread carefully, however, because it can be difficult, if not impossible, to determine in advance whether a particular practice promotes or harms competition."
Many speakers cited to a recent report issued through the Federal Trade Commission, a copy of which is found here. In the end, the executive summary of the FTC's report followed the 'caution' model: "In evaluating whether new proscriptions are necessary, we advise proceeding with caution before enacting broad, ex ante restrictions in an unsettled, dynamic environment."
The committee thanks participants on the panel -- Michael Katz, professor of economics at the University of California at Berkeley, David Sohn from the Center for Democracy and Technology, Gail Levine from Verizon, and Markham Erickson representing a group of content providers through his firm Holch & Erickson.
Thursday, August 02, 2007
Minneapolis Disaster
I've already heard from a number of members based here in the Twin Cities. I've heard nothing to this moment that suggests any of our members have been directly impacted by this event. Give me a ring or send an e-mail if you've got any particular questions or concerns.
--
Fleming